21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 11301-11350 of 21553 CVEs Page 227 of 432
CVE-2026-13473
Analyzed
8.1
IBM Storage Protect Client

IBM Storage Protect Client 8

2026-07-18
CVE-2026-13468
Analyzed
7.5
WordPress Visualizer

The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to,...

2026-07-01
CVE-2026-13461
9.6
PayRange PayRange

When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific...

2026-07-15
CVE-2026-1346
Analyzed
9.3
IBM Verify Identity

IBM Verify Identity and Security Verify Access products contain a privilege escalation vulnerability allowing locally authenticated users to gain root...

2026-04-08
CVE-2026-13449
Analyzed
7.6
IBM Business Automation Manager Open Editions

IBM Business Automation Manager Open Editions 9

2026-07-01
CVE-2026-13448
Analyzed
8.1
IBM Langflow OSS

IBM Langflow OSS 1

2026-07-18
CVE-2026-13446
Analyzed
9.8
IBM Langflow OSS

IBM Langflow OSS versions 1.0.0 through 1.10.1 contain hard-coded credentials used for authentication and internal communication, which could be explo...

2026-07-18
CVE-2026-13445
Analyzed
8.1
IBM Langflow OSS

IBM Langflow OSS 1

2026-07-18
CVE-2026-13444
Analyzed
8.1
IBM Langflow OSS

IBM Langflow OSS 1

2026-08-01
CVE-2026-13439
Analyzed
9.8
WordPress Easy Form Builder by WhiteStudio

The Easy Form Builder plugin for WordPress contains an unauthenticated privilege escalation vulnerability allowing attackers to reset any user passwor...

2026-07-21
CVE-2026-13435
Analyzed
9.9
IBM Langflow OSS

IBM Langflow OSS contains an improper input validation vulnerability in its PythonREPL sandbox implementation, allowing authenticated attackers to per...

2026-07-31
CVE-2026-13424
Analyzed
7.2
WordPress Online Scheduling and Appointment Booking System – Bookly

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_up...

2026-08-16
CVE-2026-13423
Analyzed
9.8
HP Streamit WordPress theme

The Streamit WordPress theme contains an unauthenticated AJAX vulnerability that allows remote attackers to execute arbitrary PHP functions, leading t...

2026-07-30
CVE-2026-1342
8.5
IBM Verify Identity

IBM Verify Identity Access Container 11

2026-04-08
CVE-2026-13410
Analyzed
8.2
Google Dancer::Plugin::Auth::Google

Dancer::Plugin::Auth::Google versions through 0

2026-07-18
CVE-2026-13401
Analyzed
7.5
CODECHILD XML::Bare

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances t...

2026-07-21
CVE-2026-1340
KEV Analyzed
9.8
Unknown Multiple Products

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

2026-01-30
CVE-2026-13397
Analyzed
7.5
CODECHILD HTML::Bare

HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances...

2026-07-21
CVE-2026-13395
Analyzed
8.6
WordPress Online Scheduling and Appointment Booking System

The Online Scheduling and Appointment Booking System WordPress plugin before 27

2026-07-31
CVE-2026-13385
Analyzed
9.5
Asus Router

ASUS routers are vulnerable to a man-in-the-middle attack due to improper certificate and integrity check validation, allowing attackers to force the...

2026-07-15
CVE-2026-13384
Analyzed
8.6
WatchGuard Fireware OS

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code...

2026-07-03
CVE-2026-13383
Analyzed
8.6
WatchGuard Fireware OS

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code...

2026-07-03
CVE-2026-13381
Analyzed
8.7
VSee Clinic

VSee Clinic 7

2026-07-21
CVE-2026-13378
Analyzed
7.2
WordPress Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all ver...

2026-07-12
CVE-2026-13368
Analyzed
9.2
WatchGuard Fireware OS

A use-after-free race condition in WatchGuard Fireware OS allows unauthenticated remote attackers to execute arbitrary code via the IKEv2 Mobile VPN.

2026-07-03
CVE-2026-13361
Analyzed
8.8
IBM Informix Dynamic Server

IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field

2026-08-13
CVE-2026-13360
Analyzed
7.2
WordPress WPLP Cookie Consent

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regionArray' parame...

2026-08-16
CVE-2026-13353
Analyzed
8.8
WordPress WP Ultimate CSV Importer

The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versi...

2026-07-11
CVE-2026-13352
Analyzed
8.8
WordPress Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vuln...

2026-07-17
CVE-2026-1335
Analyzed
7.8
SOLIDWORKS eDrawings

An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Re...

2026-02-17
CVE-2026-13341
Analyzed
7.4
KongHQ mcp-konnect

A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1

2026-07-05
CVE-2026-1334
Analyzed
7.8
SOLIDWORKS eDrawings

An Out-Of-Bounds Read vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Rel...

2026-02-17
CVE-2026-13339
Analyzed
7.5
WordPress CubeWP Framework

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1

2026-08-02
CVE-2026-13332
Analyzed
9.1
WordPress Masteriyo LMS

The Masteriyo LMS WordPress plugin contains an unauthenticated AJAX action that allows attackers to terminate any user session, including administrato...

2026-07-28
CVE-2026-1333
Analyzed
7.8
Intel eDrawings

A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 t...

2026-02-17
CVE-2026-13325
Analyzed
8.5
Red Hat OpenShift Virtualization

A flaw was found in KubeVirt's migration proxy

2026-06-27
CVE-2026-13321
Analyzed
8.6
ISC BIND 9

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone

2026-07-24
CVE-2026-1331
Analyzed
9.8
HP Multiple Products

MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execut...

2026-01-22
CVE-2026-13308
Analyzed
8.1
Autel MaxiCharger AC Elite Home

Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability

2026-07-30
CVE-2026-1330
7.5
MeetingHub Multiple Products

MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Pa...

2026-01-22
CVE-2026-1329
8.8
Tenda Multiple Products

A flaw has been found in Tenda AX1803 1

2026-01-23
CVE-2026-13281
Analyzed
8.3
Google Chrome

Integer overflow in Mojo in Google Chrome prior to 149

2026-06-27
CVE-2026-1328
8.8
TOTOLINK Multiple Products

A vulnerability was detected in Totolink NR1800X 9

2026-01-23
CVE-2026-13244
8.1
Drupal Tealium iQ Tag Management

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injecti...

2026-07-16
CVE-2026-1324
8.8
Unknown Multiple Products

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3

2026-01-23
CVE-2026-13233
Analyzed
9.1
Drupal OpenAI Provider

A Server-Side Request Forgery (SSRF) vulnerability in the Drupal OpenAI Provider module allows remote attackers to force the server to make unauthoriz...

2026-07-15
CVE-2026-13228
Analyzed
8.8
WordPress Calendar Booking Plugin

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in ver...

2026-07-02
CVE-2026-13221
Analyzed
9.8
Perl Perl

Perl versions through 5.43.9 contain an integer overflow in the regex trie optimizer, causing silently incorrect regular expression matches when proce...

2026-07-17
CVE-2026-1321
8.1
WordPress is vulnerable

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3

2026-03-05
CVE-2026-13206
Analyzed
9.8
Zyxel WAH7601

An OS command injection vulnerability in Zyxel WAH7601 allows unauthenticated remote attackers to execute arbitrary commands on the affected device.

2026-08-11